Using a Linux workstation as traffic analyzer, which of the following commands would gather the data requested by the client?

Posted by: Pdfprep Category: 201-450 Tags: , ,

You find that a host ( being used on one of your client’s networks has been compromised with a backdoor program listening on port 31337.

Your client requests a list of originating IP addresses connecting to that port.

Using a Linux workstation as traffic analyzer, which of the following commands would gather the data requested by the client?
A . tcpdump host and port 31337 -w out
B . nmap host
C . arpwatch -n -p 31337 > capture
D . pcap -d
E . ipwatch –syn -p 31337 –1og=out

Answer: A

Leave a Reply

Your email address will not be published.